Skip to content

ci: remove audit ignore of quick-xml advisories - #25600

Merged
alamb merged 1 commit into
apache:mainfrom
Phoenix500526:ci/audit
Sep 22, 2026
Merged

alamb merged 1 commit into
apache:mainfrom
Phoenix500526:ci/audit

Conversation

@Phoenix500526

Copy link
Copy Markdown
Contributor

Which issue does this PR close?

  • Closes #N/A.

Rationale for this change

In commit #094ad31, @alamb fixed CI failure by temporarily ignoring the two quick-xml RustSec advisories in the
audit workflow and documented that the ignores should be removed once object_store upgrades to quick-xml >= 0.41.0.

Now that PR #25335 has been merged, we can remove these temeporary ignores.

What changes are included in this PR?

Remove the two temporary audit ignores in security_audit.sh.

What is the testing strategy for this PR?

Just CI update

Are there any user-facing changes?

No

@github-actions github-actions Bot added the development-process Related to development process of DataFusion label Sep 22, 2026

@alamb alamb left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thank you @Phoenix500526

@alamb
alamb enabled auto-merge September 22, 2026 09:30
auto-merge was automatically disabled September 22, 2026 09:32

Head branch was pushed to by a user without write access

@codecov-commenter

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 82.42%. Comparing base (d42cd85) to head (3da7b03).
⚠️ Report is 1 commits behind head on main.

Additional details and impacted files
@@            Coverage Diff             @@
##             main   #25600      +/-   ##
==========================================
- Coverage   82.42%   82.42%   -0.01%     
==========================================
  Files        1140     1140              
  Lines      435552   435552              
  Branches   435552   435552              
==========================================
- Hits       359001   358984      -17     
- Misses      54838    54853      +15     
- Partials    21713    21715       +2     

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@alamb
alamb added this pull request to the merge queue Sep 22, 2026
@alamb

alamb commented Sep 22, 2026

Copy link
Copy Markdown
Contributor

Thank you @Phoenix500526

@github-merge-queue
github-merge-queue Bot removed this pull request from the merge queue due to failed status checks Sep 22, 2026
@alamb
alamb added this pull request to the merge queue Sep 22, 2026
Merged via the queue into apache:main with commit 5de9302 Sep 22, 2026
41 checks passed
Omega359 pushed a commit to Omega359/arrow-datafusion that referenced this pull request Oct 11, 2026
## Which issue does this PR close?

<!--
We generally require a GitHub issue to be filed for all bug fixes and
enhancements and this helps us generate change logs for our releases.
You can link an issue to this PR using the GitHub syntax. For example
`Closes apache#123` indicates that this PR will close issue apache#123.
-->

- Closes #N/A.

## Rationale for this change

<!--
Why are you proposing this change? If this is already explained clearly
in the issue then this section is not needed.
Explaining clearly why changes are proposed helps reviewers understand
your changes and offer better suggestions for fixes.

Please explain the problem you are trying to solve in terms of the
user-visible
behavior, rather than the implementation.

For example, "The code in `foo.rs` doesn't handle nulls" is a symptom of
the
implementation. "COUNT(DISTINCT) returns wrong results when the column
contains
nulls" is the user-visible problem.
-->

In commit #094ad31, @alamb fixed CI failure by temporarily ignoring the
two quick-xml RustSec advisories in the
audit workflow and documented that the ignores should be removed once
object_store upgrades to quick-xml >= 0.41.0.

Now that PR apache#25335 has been merged, we can remove these temeporary
ignores.



## What changes are included in this PR?

<!--
There is no need to duplicate the description in the issue here, but it
is sometimes worth providing a summary of the individual changes in this
PR.
-->

Remove the two temporary audit ignores in security_audit.sh. 

## What is the testing strategy for this PR?

<!--
We typically require tests for all PRs in order to:
1. Prevent the code from being accidentally broken by subsequent changes
2. Serve as another way to document the expected behavior of the code

Briefly describe how this PR is tested, and point to the specific tests
you added. For example: 'This new feature is covered by the
`sqllogictest` cases added in `foo.slt`'.

If this PR does not add tests, explain why. For example, if the change
is already covered by existing tests, please mention it.

You should also check the `codecov` bot reply on this PR to confirm the
changed code is exercised.
-->

Just CI update

## Are there any user-facing changes?

<!--
If there are user-facing changes then we may require documentation to be
updated before approving the PR.

If there are any breaking changes to public APIs, please add the `api
change` label.
-->
No

Signed-off-by: Jiawei Zhao <[email protected]>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

development-process Related to development process of DataFusion v56.0.0

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants